Skip to content
This repository has been archived by the owner on Oct 26, 2023. It is now read-only.

hotdog CVE-2021-3101

High
cbgbt published GHSA-qfhv-c5cc-mhgp Dec 24, 2021

Package

gomod github.com/bottlerocket-os/hotdog (Go)

Affected versions

< 1.0.1

Patched versions

1.0.1

Description

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.

Severity

High

CVE ID

CVE-2021-3101

Weaknesses

No CWEs